China-Nexus Hackers Target Linux Devices to Redirect Traffic and Deploy Malware
ID: 8d8eb01c-23d4-5f9a-b419-8fd353084557
STIX ID: report--8d8eb01c-23d4-5f9a-b419-8fd353084557
Feed Name: GBHackers
**Executive Summary:** DKnife is an advanced adversary-in-the-middle (AitM) framework that compromises Linux-based routers and edge devices to perform deep packet inspection and hijack legitimate software updates—redirecting Android APK and Windows downloads to attacker-controlled binaries and deploying backdoors such as ShadowPad and DarkNimbus; it comprises seven ELF components (e.g., dknife.bin, yitiji.bin, postapi.bin) that create a virtual local network, exfiltrate credentials, and remain active as of January 2026, with evidence linking its infrastructure to WizardNet/Spellbinder and with a focus on Chinese services and users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
